Crawld and REST API
Drive scans and read findings programmatically.
Status: Not built yet . this connector is not built. The page describes how delivery works on REST API given the constraints of the platform, and what verification would honestly be available. Today you can run the free scorecard against a REST API site without granting any access at all.
How fixes would arrive
You call the API and decide what to do with the result. Nothing is written on your behalf.
The API is the substrate the other integrations sit on rather than an integration itself. What it can deliver depends entirely on what access you have granted alongside it.
The strongest rung. Because we hold the repository, the change can be built before you ever see it, and the pull request carries the result of that build. Nothing merges without your click.
What the rubric can see here
- Queue a scan for a URL and poll it to completion
- Read the scorecard: overall score, per-category scores, coverage
- Read the findings list once a scan is unlocked
Limits worth knowing before you plan around this
- The public scan surface is unauthenticated, rate limited to 3 submissions an hour per caller, and capped at 10 pages per crawl
- One real crawl per domain per day: repeat calls return that day’s scan rather than re-crawling
- The authenticated API is not documented publicly yet
Where this sits on the ladder
| Mode | What we get | How changes arrive | Verification | Status |
|---|---|---|---|---|
| A · Repo write | A connected repository we can push a branch to | Opens a pull request. You review the diff and merge it. | Build-verified | Not built yet |
| B · Read-only repo | Read access, plus somewhere to push | Pushes to a fork or a branch you own. | Build-verified | Not built yet |
| C · Cloud mirror | A one-time snapshot or export | Works on a clone in our cloud, returns a patch or a PR. | Build-verified (mirror) | Not built yet |
| D · CMS drafts | OAuth into a hosted CMS | Writes unpublished drafts. You publish them. | Preview-verified | Not built yet |
| E · URL only | Nothing: a public URL | A scorecard and a patch you apply yourself. | Advisory only | Available now |
Build-verified means a build actually ran. It applies to modes A, B and C and to nothing else. A hosted CMS has no build to run, so mode D is preview-verified and mode E is advisory. Those labels are never blurred, because the honesty of the verification is the product.
What you can do today
Scan the site. The free scorecard needs no access to REST API at all. It reads the published HTML the way a search or answer engine does, runs the full 129-check rubric against it, and reports what it could not measure rather than counting it as a pass.
Everything it finds is actionable by hand regardless of whether a connector ever exists, because the finding names the page and the change rather than a button to press.